Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Defender for Cloud to secure its hybrid cloud workload. The security team needs to ensure that all virtual machines (VMs) have Just-In-Time (JIT) VM access enabled. What should they use to enforce this across subscriptions?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign an Azure Policy initiative that requires JIT VM access

Azure Policy can enforce JIT VM access via a built-in initiative. Assigning an Azure Policy initiative across subscriptions ensures that any VM without JIT VM access enabled is non-compliant and can be remediated. Option B (Azure Blueprints) is an orchestration tool that can deploy resources but does not enforce configuration across subscriptions at scale. Option C (Defender for Cloud servers plan) enables security features but does not enforce specific settings like JIT. Option D (Secure Score recommendations) is advisory and does not enforce compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign an Azure Policy initiative that requires JIT VM access

    Why this is correct

    Assigning an Azure Policy initiative is the most effective method for enforcing Just-in-Time (JIT) VM access across an Azure environment. An initiative groups multiple policy definitions, allowing for comprehensive governance and consistent application of security controls. When assigned, it can audit for non-compliant resources and automatically remediate them to ensure all virtual machines adhere to the JIT access requirement, thereby significantly reducing the attack surface.

  • Use Azure Blueprints to deploy JIT access configuration

    Why it's wrong here

    Azure Blueprints were a service designed for deploying repeatable sets of Azure resources and configurations, but they have been deprecated by Microsoft. The recommended approach for achieving similar outcomes, especially for ongoing governance and compliance enforcement like JIT access, is now a combination of Azure Deployment Stacks for resource deployment and Azure Policy. Therefore, attempting to use Blueprints for JIT access configuration is an outdated and unsupported approach.

  • Enable the Defender for Cloud servers plan

    Why it's wrong here

    Enabling the Microsoft Defender for Cloud servers plan provides advanced threat protection, vulnerability assessments, and security alerts for virtual machines. While it integrates with JIT VM access by providing recommendations and monitoring capabilities, the plan itself does not enforce the JIT access configuration. Its primary role is detection, protection, and response against threats, not policy-driven access control enforcement.

  • Implement a Secure Score recommendation for JIT access

    Why it's wrong here

    Implementing a Secure Score recommendation for JIT access involves reviewing and acting upon security suggestions provided by Microsoft Defender for Cloud. Secure Score is a measurement of an organization's security posture and offers actionable advice to improve it by highlighting areas needing attention. However, it is a reporting and guidance tool, not an enforcement mechanism; it recommends changes but does not automatically apply or mandate JIT access.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.